Page tree
Skip to end of metadata
Go to start of metadata

Overview

In cPanel & WHM version 11.40 and earlier, visitors who accessed a website via https without an SSL configuration saw a connection error. 

In cPanel & WHM version 11.42 and later, we modified Apache's configuration to properly use proxy subdomains with SSL.

  • Proxy subdomain virtualhosts now handle SSL and non-SSL connections separately.
  • Each proxy subdomain virtualhost explicitly binds to all of the assigned IP addresses on a server.
  • SSL virtualhost configurations—such as the cpanel, whm, webdisk, and webmail proxy subdomains—use the cPanel service SSL certificate. 

In cPanel & WHM version 62 and later, cPanel & WHM enables SNI functionality by default for SSL certificates on proxy subdomains. SNI allows multiple SSL certificates to use a single IP address and port number.

Due to these changes, Apache uses cPanel's service SSL certificate to secure websites that do not have an SSL certificate. Visitors to sites without an SSL certificate may see an SSL warning, because Apache used cPanel's service SSL certificate to secure the site.

How to bypass the use of proxy subdomains and the cPanel service SSL certificate

Warning:

We do not recommend that you bypass your server's proxy subdomain configuration.

To prevent the use of the cPanel service SSL certificate for the cpanel, whm, webdisk, and webmail subdomains, you must perform the following steps:

  1. Disable the Proxy subdomains setting in the Domains section of WHM's Tweak Settings interface (Home >> Server Configuration >> Tweak Settings).
  2. Use cPanel's Subdomains interface (Home >> Domain >> Subdomains) to manually create each service's subdomain (for example, cpanel, whm, webdisk, and webmail).
  3. Redirect each service's subdomain to the appropriate secure URL and port as follows:

    ServiceSubdomainRedirection
    cPanelcpanel.example.comhttps://example.com:2083
    WHMwhm.example.com
    https://example.com:2087
    Web Diskwebdisk.example.com https://example.com:2078
    Webmailwebmail.example.com https://example.com:2096

When you navigate to webmail.example.com, the server redirects you to https://example.com:2096 and uses the example.com domain's SSL certificate to secure the connection.

Additional documentation